Threat reportVulnerabilityTL-2026-0040
Microsoft NTLM Deprecation - Three-Stage Phase-Out Plan
Microsoft NTLM Deprecation (TL-2026-0040), also tracked as NTLM Relay, is a high-severity software vulnerability scored CVSS 7.5, first published 2026-02-03. It has no confirmed attribution, affects Microsoft Windows Server and Windows Client, maps to 19 MITRE ATT&CK techniques (T1003, T1003.003, T1018), and is covered by 15 detection rules and 40 indicators of compromise.
- CVSS
- 7.5/10High
- CVEs
- 0None referenced
- Techniques
- 19MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 15SPL · KQL · Sigma
- IOCs
- 40Indicators of compromise
Key facts for TL-2026-0040
- Threat ID
- TL-2026-0040
- Also known as
- NTLM Relay, Pass-the-Hash, NTLM Deprecation
- Severity
- HIGH
- CVSS
- 7.5 (N/A - Protocol Weakness)
- Status
- MONITORING
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- VARIOUS
- Target sectors
- Enterprise, Government, Financial Services, Healthcare, Education, Manufacturing, All sectors running Active Directory
- Target regions
- Global
- Detection rules
- 15
- Indicators of compromise
- 40
Malware and tooling in Microsoft NTLM Deprecation
Malware and tooling: Impacket ntlmrelayx.py / Responder / PetitPotam.py / DFSCoerce.py / mimikatz, ntlmrelayx.py / Responder / PetitPotam.py / DFSCoerce.py / mimikatz / Rubeus
How Microsoft NTLM Deprecation works
Microsoft's three-stage NTLM deprecation plan: enterprise migration timeline from NTLM to Kerberos/Negotiate, legacy application compatibility matrix, and the operational risk of a 30-year protocol phase-out across millions of Active Directory environments.
Microsoft announced the formal deprecation of NTLM authentication in June 2024 with a phased three-stage approach to remove the protocol from Windows. This threat covers the ENTERPRISE MIGRATION perspective — distinct from TL-0018 (NTLM enforcement and the attack surface). Stage 1 (Audit & Discovery, 2024-2025): Organizations enable NTLM auditing via Group Policy (Network Security: Restrict NTLM: Audit NTLM authentication in this domain / Audit Incoming NTLM Traffic) to discover all applications, services, and systems still using NTLM. Windows Event IDs 8001-8004 log NTLM usage. This phase reveals the true scope of NTLM dependency — most enterprises discover 10-40% of authentication traffic is still NTLM. Stage 2 (Selective Restriction, 2025-2026): Organizations begin blocking NTLM for specific applications and services using NTLM restriction policies (Network Security: Restrict NTLM: NTLM authentication in this domain / Add server exceptions). Server-side and client-side exceptions manage compatibility. IAM Credential Roaming exceptions handle legacy device authentication. This phase exposes the COMPATIBILITY MATRIX problem: legacy applications (pre-2010 LOB apps, older ERP systems, embedded devices, legacy printers, cross-forest trusts, non-Windows clients) that cannot negotiate Kerberos. Stage 3 (Full Deprecation, 2026+): Microsoft removes NTLM components from Windows. NTLMv1 removed first (immediate security gain — NTLMv1 hashes are crackable in seconds). NTLMv2 removal follows (harder — NTLMv2 is still cryptographically weak but some services have no Kerberos path). The compatibility matrix is the critical challenge: (1) Legacy LOB applications: custom-built .NET/COM applications using NTLM directly via SSPI rather than Negotiate. Many have hardcoded NTLM providers. Remediation: code modification or wrapper. (2) Cross-forest trusts: NTLM is required for some cross-forest authentication scenarios where Kerberos trust paths don't exist. Remediation: establish Kerberos forest trusts or migrate to Azure AD/Entra ID. (3) Non-Windows clients: Linux/macOS clients using NTLM for SMB/CIFS access. Remediation: configure Kerberos on non-Windows clients (krb5.conf + keytab). (4) Embedded devices: printers, scanners, ICS/OT devices with hardcoded NTLM. Remediation: network segmentation + service accounts with NTLM exceptions. (5) Older SQL Server instances: pre-2016 SQL Server using NTLM for Windows authentication. Remediation: upgrade or configure SPN for Kerberos. (6) Web applications using Windows Integrated Authentication (WIA) with NTLM fallback: IIS sites configured for NTLM rather than Negotiate. Remediation: change IIS authentication provider order. The migration risk is operational disruption: blocking NTLM without completing the compatibility audit causes authentication failures that break production applications, prevent users from accessing file shares, and disrupt cross-domain trust relationships. The security risk of NOT migrating: NTLM relay attacks (ntlmrelayx), pass-the-hash, reflection attacks, and credential theft via LLMNR/NBT-NS poisoning remain the #1 Active Directory attack surface. Every day NTLM remains enabled is another day attackers can relay, capture, and crack NTLM hashes.
MITRE ATT&CK techniques used in TL-2026-0040
credential-access
T1003 OS Credential Dumping; T1003.003 NTDS; T1040 Network Sniffing; T1110 Brute Force; T1187 Forced Authentication; T1557 Adversary-in-the-Middle; T1557.001 Name Resolution Poisoning and SMB Relay; T1649 Steal or Forge Authentication Certificates
discovery
T1018 Remote System Discovery; T1046 Network Service Discovery
lateral-movement
execution
T1047 Windows Management Instrumentation
defense-evasion
T1078 Valid Accounts; T1550 Use Alternate Authentication Material; T1550.002 Pass the Hash
persistence
initial-access
T1190 Exploit Public-Facing Application
privilege-escalation
T1548 Abuse Elevation Control Mechanism
resource-development
Affected products and versions in Microsoft NTLM Deprecation
- Microsoft — Windows Server and Windows Client
Vulnerable versions: All versions using NTLM
Fixed in: Kerberos-only configurations
Remediation for Microsoft NTLM Deprecation
Immediate actions
- Audit NTLM usage with provided detection queries
- Identify applications and services requiring NTLM
- Disable NTLMv1 via Group Policy immediately
- Enable NTLM auditing (GPO: Network security: Restrict NTLM)
- Block NTLM where possible using network policies
Workarounds
- Restrict NTLM to specific servers/applications via GPO
- Enable Extended Protection for Authentication (EPA)
- Require NTLMv2 minimum via LmCompatibilityLevel
Longer-term hardening
- Migrate all authentication to Kerberos
- Upgrade or replace legacy applications requiring NTLM
- Implement modern authentication (Azure AD, OIDC)
- Prepare for NTLM-disabled Windows versions
- Deploy credential guard to protect NTLM hashes
Weaknesses (CWE) in Microsoft NTLM Deprecation
Timeline of Microsoft NTLM Deprecation
- NTLM authentication introduced in Windows NT 3.1. Challenge-response protocol replacing plaintext LAN Manager authentication. Designed for single-domain environments. Source: Microsoft.
- Discovered
- First Exploitation
- Windows 2000 introduces Kerberos v5 as the preferred authentication protocol for Active Directory. NTLM remains as fallback for backward compatibility. Microsoft recommends Kerberos over NTLM. Source: Microsoft.
- Windows 7 / Server 2008 R2 introduces NTLM restriction and auditing Group Policy settings. Organizations can now audit and selectively block NTLM usage. Source: Microsoft.
- Impacket ntlmrelayx and Responder become mature attack tools. NTLM relay attacks industrialized — automated capture and relay of NTLM hashes in penetration testing and real attacks. Source: Multiple.
- PetitPotam attack (CVE-2021-36942) demonstrates NTLM relay via MS-EFSRPC. Forces domain controller to authenticate to attacker via NTLM — enables full domain compromise. Source: Topotam/GitHub.
- DFSCoerce attack discovered — NTLM relay via MS-DFSNM. Another coercion vector forcing NTLM authentication from domain controllers. Compounds the urgency for NTLM deprecation. Source: GitHub.
- CVE-2023-23397: Microsoft Outlook NTLM hash leak via calendar invitation. Zero-click NTLM hash theft exploited by Russian APT28. Demonstrates that NTLM vulnerabilities are actively weaponized. Source: Microsoft MSRC.
- Microsoft formally announces NTLM deprecation. Three-stage phase-out plan published. Windows Server 2025 includes built-in deprecation features. 30+ year protocol begins sunset. Source: Microsoft.
- Disclosed
- Windows Server 2025 released with enhanced NTLM auditing, restriction controls, and deprecation path tooling. Stage 1 tooling available for enterprises. Source: Microsoft.
- Stage 1 (Audit & Discovery) active. Enterprises discover 10-40% of authentication traffic is NTLM. Legacy LOB applications, cross-forest trusts, and embedded devices identified as primary blockers. Source: Industry reports.
- Stage 2 (Selective Restriction) begins for early adopters. NTLMv1 disabled across most environments. NTLMv2 restrictions applied to migrated services. Exception lists grow for legacy systems. Source: Microsoft guidance.
- Stage 3 (Full Deprecation) planning underway. NTLMv1 removal from Windows confirmed. NTLMv2 removal timeline tied to enterprise migration progress. Legacy device exception strategy required. Source: Microsoft roadmap.
- Patch Available
- As of 2026-05-29, this NTLM-deprecation lifecycle threat remains active: Microsoft's three-stage phase-out is mid-flight (Phase 1 auditing live on Server 2025/Win11 24H2, NTLMv1 already removed, Phase 2 IAKerb/local-KDC due H2 2026, Oct 2026 BlockNTLMv1SSO enforce, Phase 3 undated). The relay/pass-the-hash/PetitPotam attack surface is still exploited in 2026, so MONITORING holds.
Sources cited for Microsoft NTLM Deprecation
- The Hacker News: Microsoft Begins NTLM Phase-Out With Three-Stage Plan
- Microsoft Security Blog: NTLM Deprecation
- Microsoft: NTLM Overview — Windows Server
- Microsoft: NTLM Deprecation — Windows IT Pro Blog
- Microsoft: Restrict NTLM GPO Settings
- Microsoft: Kerberos Authentication Overview
- Microsoft: Windows Server 2025 Features
- MITRE ATT&CK: NTLM Relay T1557.001
- MITRE ATT&CK: Pass the Hash T1550.002
- Impacket ntlmrelayx
- Responder — LLMNR/NBT-NS Poisoner
- PetitPotam — CVE-2021-36942
- DFSCoerce — MS-DFSNM Coercion
- CVE-2023-23397: Outlook NTLM Hash Leak
- CIS Microsoft Windows Server Benchmark
Detection coverage for TL-2026-0040
As of 2026-02-03, Threadlinqs Intelligence publishes 15 detection rule(s) for TL-2026-0040 across Splunk SPL, Microsoft KQL and Sigma, covering 40 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.